ISO 27001 & Data Security Certifications
Navigo maintains the following data security certifications:
-
ISO/IEC 27001:2022 certified, valid to 24 April 2029. Scope includes the applications licensed to Navigo and the data it stores and processes. This includes the maintenance, configuration, support and professional services relating to the HR applications.
-
DISP (Defence Information Security Program) certified. Our Solutions Architects have Baseline security clearance.
-
A member of the Australian Cyber Security Centre Partnership Program, including Essential Eight compliance at Maturity Level One (November 2023 model).

Microsoft Azure
org.manager is hosted by Navigo on Microsoft Azure (NSW, Australia).
Azure Data Centres are ISO 27001 certified and IRAP assessed.
Data Location: Australia East (Sydney, NSW)
Azure Data Centre Certifications: Microsoft's Azure data centre operations have been accredited under:
-
Australian Government Information Security Registered Assessor Program (IRAP)
-
ISO 27001 - ISO/IEC 27001:2013 Information Security Management Standards
-
SOC 1 and SOC 2/SSAE 16/ISAE 3402 (Previously SAS 70 Type II)
Ingentis
Ingentis, the vendor of org.manager, is ISO 27001 certified. org.manager has been independently audited and holds a SOC 2 Type 2 report.
org.manager utilises OpenVAS tools for vulnerability management.